plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.098
EPSS Ranking 92.6%